VendorsWSO2identity_serverall versions
Vulnerabilities

WSO2 Identity Server

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

83CVEs
CVE-2023-6838
Reflected XSS vulnerability can be exploited by tampering a request parameter in Authentication Endpoint. This can be performed in both authenticated and unauthenticated requests.
Published 2023-12-15 · Modified
6.1EPSS 0.004
CVE-2025-8591
Reflected Cross-Site Scripting via URL Parameter in Multiple WSO2 Products Enables UI Modification
Published 2026-07-06 · Analyzed
6.1EPSS 0.003
CVE-2026-2445
Reflected Cross-Site Scripting via URL Parameter in Multiple WSO2 Products Enables UI Redirection and Modification
Published 2026-07-20 · Analyzed
6.1EPSS 0.003
CVE-2024-5962
Reflected Cross-Site Scripting (XSS) in Authentication Endpoint of Multiple WSO2 Products Due to Missing Output Encoding
Published 2025-05-22 · Analyzed
6.1EPSS 0.003
CVE-2025-0209
Reflected Cross-Site Scripting (XSS) in WSO2 Identity Server Account Registration Flow
Published 2025-09-23 · Analyzed
6.1EPSS 0.002
CVE-2025-6024
Cross-Site Scripting via Authentication Endpoint in Multiple WSO2 Products Allows Redirection to Malicious Websites
Published 2026-04-16 · Analyzed
6.1EPSS 0.002
CVE-2024-1440
Open Redirection in Multiple WSO2 Products via Multi-Option Authentication Endpoint
Published 2025-06-02 · Analyzed
6.1EPSS 0.002
CVE-2025-5770
Reflected Cross-Site Scripting (XSS) in Authentication Endpoints of Multiple WSO2 Products
Published 2025-11-05 · Analyzed
6.1EPSS 0.002
CVE-2025-10853
Reflected Cross-Site Scripting (XSS) in Management Console of Multiple WSO2 Products Due to Improper Output Encoding
Published 2025-11-05 · Analyzed
6.1EPSS 0.002
CVE-2025-10503
Reflected Cross-Site Scripting via Authentication Endpoint in WSO2 Identity Server
Published 2026-04-29 · Analyzed
6.1EPSS 0.002
CVE-2025-12624
Improper Token Invalidation in WSO2 Identity Server Allows Access After Account Lock
Published 2026-04-16 · Analyzed
6.0EPSS 0.002
CVE-2025-5350
SSRF and Reflected XSS Vulnerability in Deprecated Try-It Feature of Multiple WSO2 Products
Published 2025-10-24 · Analyzed
5.9EPSS 0.006
CVE-2024-7487
Improper Authentication in WSO2 Identity Server 7.0.0 Allows Bypass of App-Native Authentication
Published 2025-05-22 · Analyzed
5.8EPSS 0.003
CVE-2024-10302
Improper Input Validation via Signup Process in Multiple WSO2 Products Enables Content Manipulation and Data Exposure
Published 2026-08-06 · Undergoing Analysis
5.8EPSS 0.003
CVE-2024-2321
Incorrect Authorization in Multiple WSO2 Products Allows API Access via Refresh Token
Published 2025-02-27 · Analyzed
5.6EPSS 0.002
CVE-2018-8716
WSO2 Identity Server before 5.5.0 has XSS via the dashboard, allowing attacks by low-privileged attackers.
Published 2018-04-25 · Modified
5.41 PoCEPSS 0.387
CVE-2018-20737
An issue was discovered in WSO2 API Manager 2.1.0 and 2.6.0. Reflected XSS exists in the carbon part of the product.
Published 2019-03-18 · Modified
5.4EPSS 0.010
CVE-2024-7096
Privilege Escalation in Multiple WSO2 Products via SOAP Admin Service Due to Business Logic Flaw
Published 2025-05-30 · Modified
5.4EPSS 0.007
CVE-2020-14444
An issue was discovered in WSO2 Identity Server through 5.9.0 and WSO2 IS as Key Manager through 5.9.0. A potential Reflected Cross-Site Scripting (XSS) vulnerability has been identified in the Management Console Policy Administration user interface.
Published 2020-06-18 · Modified
5.4EPSS 0.007
CVE-2020-14445
An issue was discovered in WSO2 Identity Server through 5.9.0 and WSO2 IS as Key Manager through 5.9.0. A potential Reflected Cross-Site Scripting (XSS) vulnerability has been identified in the Management Console Basic Policy Editor user Interface.
Published 2020-06-18 · Modified
5.4EPSS 0.006
CVE-2024-7103
Reflected Cross-Site Scripting (XSS) in WSO2 Identity Server 7.0.0 Sub-Organization Login Flow
Published 2025-05-22 · Analyzed
5.4EPSS 0.002
CVE-2025-13394
Cross-Site Request Forgery via Ajax Processor Endpoints in Multiple WSO2 Products Enables Unauthorized Actions
Published 2026-08-06 · Analyzed
5.4EPSS 0.001
CVE-2025-5605
Authentication Bypass via URI Manipulation in Multiple WSO2 Products' Management Console Leading to Partial Information Disclosure
Published 2025-10-24 · Analyzed
5.3EPSS 0.009
CVE-2024-1248
Role Overwriting via Silent JIT Provisioning in Multiple WSO2 Products Enables Privilege Escalation
Published 2026-07-04 · Analyzed
5.3EPSS 0.003
CVE-2025-1396
Username Enumeration in Multiple WSO2 Products with Multi-Attribute Login Enabled
Published 2025-09-26 · Analyzed
5.3EPSS 0.003
CVE-2024-0391
Username Enumeration via Email OTP Flow in Multiple WSO2 Products Allows User Account Discovery
Published 2026-05-11 · Analyzed
5.3EPSS 0.002
CVE-2024-8008
Reflected Cross-Site Scripting (XSS) in Multiple WSO2 Products via JDBC User Store Connection Validation
Published 2025-06-02 · Analyzed
5.2EPSS 0.005
CVE-2024-8995
Authorization Code issued for Deleted User reuse in Multiple WSO2 Products Allows Unauthorized Access
Published 2026-08-06 · Analyzed
4.9EPSS 0.002
CVE-2017-14651
WSO2 Data Analytics Server 3.1.0 has XSS in carbon/resources/add_collection_ajaxprocessor.jsp via the collectionName or parentPath parameter.
Published 2017-09-21 · Modified
4.8EPSS 0.038
CVE-2019-20443
An issue was discovered in WSO2 API Manager 2.6.0, WSO2 Enterprise Integrator 6.5.0, WSO2 IS as Key Manager 5.7.0, and WSO2 Identity Server 5.8.0. A potential stored Cross-Site Scripting (XSS) vulnerability in mediaType has been identified in the registry UI.
Published 2020-01-27 · Modified
4.8EPSS 0.008
CVE-2019-20442
An issue was discovered in WSO2 API Manager 2.6.0, WSO2 Enterprise Integrator 6.5.0, WSO2 IS as Key Manager 5.7.0, and WSO2 Identity Server 5.8.0. A potential stored Cross-Site Scripting (XSS) vulnerability in roleToAuthorize has been identified in the registry UI.
Published 2020-01-27 · Modified
4.8EPSS 0.007
CVE-2023-6911
Multiple WSO2 products have been identified as vulnerable due to improper output encoding, a Stored Cross Site Scripting (XSS) attack can be carried out by an attacker injecting a malicious payload into the Registry feature of the Management Console.
Published 2023-12-18 · Modified
4.8EPSS 0.004
CVE-2026-0637
Sensitive Information Disclosure via Event Publisher Logging in Multiple WSO2 Products
Published 2026-08-06 · Analyzed
4.4EPSS 0.002
CVE-2024-7097
Incorrect Authorization in Multiple WSO2 Products via SOAP Admin Service Allowing Unauthorized User Signup
Published 2025-05-30 · Analyzed
4.3EPSS 0.007
CVE-2025-13909
Information Disclosure via Multi-Tenant Authentication Flows in WSO2 Identity Server Allows Cross-Tenant PII Exposure
Published 2026-08-06 · Analyzed
4.3EPSS 0.003
CVE-2025-11850
Improper Implicit Association via User Store Initialization in WSO2 Identity Server [Identity Confusion / External IDP Use]
Published 2026-08-06 · Analyzed
4.3EPSS 0.003
CVE-2024-6429
Content Spoofing in Multiple WSO2 Products via Error Message Injection
Published 2025-09-23 · Analyzed
4.3EPSS 0.002
CVE-2024-3511
Incorrect Authorization in Multiple WSO2 Products Allows Unauthorized Access to Registry Versioned Files
Published 2025-06-23 · Analyzed
4.3EPSS 0.002
CVE-2024-3509
Stored Cross-Site Scripting (XSS) in Management Console of Multiple WSO2 Products via Rich Text Editor
Published 2025-06-02 · Analyzed
4.3EPSS 0.002
CVE-2025-14779
Improper Access Control via Secret Type Management API in WSO2 Identity Server
Published 2026-08-06 · Analyzed
3.8EPSS 0.003
← Prev2 / 3Next →